Files
Codeman/scripts/codeman-web.service
arkonandClaude Opus 4.8 8453e953fd chore(service): sync codeman-web.service template with the deployed unit
Reconcile scripts/codeman-web.service with the installed
~/.config/systemd/user/codeman-web.service so they're identical: carry the
loopback + `tailscale serve` security note, keep NODE_COMPILE_CACHE, and a
concise CODEMAN_GESTURE comment. Points at docs/security-architecture.md.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 19:34:36 +02:00

34 lines
1.0 KiB
Desktop File

[Unit]
Description=Codeman Web Server
After=network.target
[Service]
Type=simple
WorkingDirectory=/home/arkon/default/claudeman
ExecStart=/usr/bin/node dist/index.js web --https
Restart=always
RestartSec=5
KillMode=process
Environment=NODE_ENV=production
Environment=HOME=/home/arkon
Environment=NODE_COMPILE_CACHE=/home/arkon/.codeman/compile-cache
# Loopback bind (default, no --host) + no password: safe out of the box. Hooks
# reach 127.0.0.1, and `tailscale serve` fronts it on the tailnet only (real
# cert, no LAN exposure, no app login). To expose on the LAN instead, add
# Environment=CODEMAN_HOST=0.0.0.0 + Environment=CODEMAN_PASSWORD=... .
# See docs/security-architecture.md.
Environment=CODEMAN_GESTURE=1
# ^ Makes the gesture-control overlay AVAILABLE (CSP widening + /gesture/ assets);
# the actual on/off stays the per-user App Settings toggle (default OFF).
# Logging
StandardOutput=journal
StandardError=journal
SyslogIdentifier=codeman
# Resource limits
LimitNOFILE=65536
[Install]
WantedBy=default.target